Recommended QoS Configuration Settings for Fortinet FortiGate 30D Router
Recommended QoS Configuration Fortinet FortiGate 30D Contents Contents Introduction....................................... 3 Supported browsers for test.............................. 3 Quality of Service.................................... 4 Test your connection capacity............................. 4 Test your connection quality.............................. 5 Configure your router................................. 6 Fortinet FortiGate 30D QoS configuration....................... 6 Port and firewall settings for mobile and softphone apps............. 14 2
Recommended QoS Configuration Fortinet FortiGate 30D Introduction Introduction Supported browsers for test RingCentral has taken the guesswork out of router selection. Since we know that Quality of Service (QoS) is paramount to your business, we have carefully selected and tested a set of dependable routers suitable for supporting high quality Voice-over-IP conversations. Internet Explorer 11 or higher (Windows XP, 7, 8 or higher) Firefox version 36 or higher (Windows and Mac) Safari version 6.2 or higher (Mac) This document provides recommended configuration settings to ensure the highest possible QoS for voice calls on the Fortinet FortiGate 30D router. Additional routers tested and recommended are the Dell SonicWALL SOHO, and the AdTran NetVanta 3448. Recommended settings to optimize QoS for VoIP calls for these routers are presented in separate documents. Dell SonicWALL SOHO AdTran NetVanta 3448 Note: The routers recommended here are quality hardware that we have tested internally and work reliably with our services. However, given the constantly updated firmware and physical changes made by manufacturers and the nature of cloud-based services, RingCentral cannot control the final configuration of the hardware or your computer systems/networks, or promise that any given router will work with your system, or guarantee that our information is 100% up to date. 3
Recommended QoS Configuration Fortinet FortiGate 30D Quality of Service Quality of Service RingCentral provides reliable, high-quality voice service. Your local network, Internet connection, and your router all contribute to overall call quality, with sufficient dedicated bandwidth to voice calls being the biggest factor. To help you manage your call quality, RingCentral offers tools to check your Internet connection speed, and instructions to configure the Quality of Service (QoS) settings of your routers. The Quality of Service (QoS) settings on your router enable it to give priority to real time voice traffic over lower priority data traffic, such as large downloads. This document provides recommended configuration settings to ensure the highest possible QoS on the Fortinet FortiGate 30D router. After configuring your router for optimum QoS, select port and firewall settings for mobile and softphone apps from the table here. Test your connection capacity The RingCentral Connection Capacity test will help determine the maximum number of simultaneous RingCentral calls that can be supported on your broadband connection. Run this test during normal business hours when the connection is in use by other applications, including large file downloads. The capacity test should be run using the maximum number of simultaneous call connections needed, and should use the G.711 codec selection. Specific requirements for QoS: Bandwidth 100Kbps up and down per call; Latency (one-way) less than 150ms; Jitter not to exceed 100ms; Packet loss less than 3%. These requirements are the foundation for ensuring your local network can support satisfactory VoIP. Failure to meet these requirements will result in poor voice quality. When the test completes, you will see the recommended number of simultaneous calls your connection can support while maintaining good quality voice calls. 4
Recommended QoS Configuration Fortinet FortiGate 30D Quality of Service Test your connection quality RingCentral provides a VoIP Quality test that will simulate VoIP calls between your computer and RingCentral, and provide an estimate of the voice quality you should expect when using our service. For the most accurate results, run this test at least three different times throughout a business day, and during peak usage times, while connected to the network that you plan to use for RingCentral. A two-minute test is typically sufficient, while longer tests are useful to find intermittent problems or to simultaneously test VoIP performance along with other traffic such as file transfers or remote access. Select the maximum number of simultaneous users you expect to support, and set the test duration between 1 and 5 minutes; 2 minutes is considered sufficient in most instances. Click jitter and packet loss on the RESULTS SUMMARY panel to view the overall quality of your expected VoIP connection. MOS score (Mean Opinion Score) refers to a test that has been used for decades in telephony networks to obtain the human user's view of the quality of the network. The MOS is the arithmetic mean of all the individual scores, and can range from 1 (worst) to 5 (best). An MOS score of 4 is good. 5
Configure your router Fortinet FortiGate 30D QoS configuration Brand: Model: Hardware version: Firmware version: Fortinet FortiGate 30D 30D FortiOS v5.2.4 To review the guide that covers configuring QoS in the FortiOS operating system click here. 1. Access the router on your LAN default gateway: 192.168.1.99. The default username is admin and the default password is blank (none). Then click OK. 6
2. When first configuring the 30D for RingCentral service you have to enter several commands on the CLI console. A) Log into CLI (click on the CLI console window from the status page). B) Log into CLI. C) Reboot router. 7
D) Log back into CLI. 3. Once the command line entries have been done you can proceed with the web GUI setup. Go to Policy & Objects > Objects > Traffic Shapers. Click Create New. Type: Shared Name: RC VoIP Apply shaper: All policies using this shaper Traffic Priority: High Check the box next to Max Bandwidth; then define based on available bandwidth. Check the box next to Guaranteed Bandwidth; then define based on expected call use. Check the box next to DSCP; then enter: 101110 8
4. Go to Policy & Objects > Policy. Click IPv4. Click Create New. A) Incoming Interface: LAN B) Source Address: All C) Outgoing Interface: WAN D) Destination Address: Click Add button E) Click Create. Name: RC Network 1 Type: IP/Netmask Subnet/IP Range: 199.255.120.0/255.255.252.0 Interface: WAN F) Click OK. 9
5. Click Add button again. Name: RC Network 2 Type: IP/Netmask Subnet/IP Range: 199.68.212.0/255.255.252.0 Interface: WAN 6. Click OK. 7. Schedule: Always. 8. Service: Click Add button. 10
9. Click Create. Name: RC VoIP SIP RTP Category: VoIP, Messaging & Other Applications Protocol Type: TCP/UDP/SCTP Protocol: 1. UDP 1000 65535 2. TCP 5060 6000 3. TCP 80 80 4. TCP 443 443 5. UDP 123 123 Note: Select applicable TCP/UDP port ranges, as needed, for your mobile and softphone apps from this table. 11
10. Traffic shaping. Shared Shaper: Set to RC VoIP Reverse Shaper: Set to RC VoIP 12
11. Go to Policy & Objects > Policy > Click on IPv4. Click Create New. A) Incoming Interface: WAN B) Source Address: Click Add button i. RC Network 1 ii. Hit Add button iii RC Network 2 C) Outgoing Interface: LAN D) Destination Address: all E) Schedule: always F) Service: Click Add button i RC VoIP SIP RTP G) Traffic Shaping: i Shared Shaper: Set to RC VoIP ii. Reverse Shaper: Set to RC VoIP Congratulations. You have finished configuring your Fortinet FortiGate 30D firewall/ router for QoS prioritization of voice packets. Now select the port and firewall settings for mobile and softphone apps from the table on the next page. 13
Recommended QoS Configuration Fortinet FortiGate 30D Port and firewall settings for mobile and softphone apps Port and firewall settings for mobile and softphone apps 2015 RingCentral, Inc. All rights reserved. RingCentral and the RingCentral logo are registered trademarks of RingCentral, Inc. Other third-party marks and logos displayed in this document are the trademarks of their respective owners. KID-828 14